CA K Sanjay BhargavChartered Accountant
Open menu
← All articles

DPDP Rules: what applies to your company, and when

CA K Sanjay Bhargav, Chartered Accountant, Bengaluru

Membership No. 250054 · DISA (ICAI)

Published

Short answer: the DPDP Rules were notified on 13 November 2025. The Data Protection Board exists now. Consent manager provisions commence 12 November 2026. Almost everything else that imposes an obligation on your business — notice, consent, security safeguards, breach reporting, data principal rights — commences 12 May 2027.

Much of the DPDP material online was written while the Rules were still in draft, and reads as though nothing is settled. That is no longer the position. The dates below are the notified ones.

Where the law actually stands

PhaseFromWhat commences
Immediate13 Nov 2025Rules 1, 2 and 17–21 — constitution and functioning of the Data Protection Board, appointments, inquiry procedure
12 months12 Nov 2026Rule 4 — registration and obligations of consent managers
18 months12 May 2027Rules 3, 5–16, 22, 23 — notice, consent, security safeguards, breach notification, children's data, Significant Data Fiduciary obligations, data principal rights, cross-border transfer

Two implications people miss.

First, the Board is already operational. The institutional machinery was brought into force immediately, ahead of the obligations it will eventually enforce. The enforcement body exists before the duties bite.

Second, there is no grace period built into the design. The eighteen months is the transition window. A company that starts in early 2027 is not starting early.

As of this writing, roughly nine months remain before the substantive obligations commence.

Does it apply to us?

Almost certainly, if you process personal data in digital form.

There is no turnover threshold, no headcount threshold and no sector gate in the Act. If you hold an employee database, a customer or client list, vendor contact details, CCTV footage tied to identifiable people, or a website form that collects enquiries, you are processing digital personal data and you are a Data Fiduciary in respect of it.

What varies with size and risk is not whether the law applies but how much is proportionate — and whether the Central Government notifies you as a Significant Data Fiduciary, which adds a further layer.

For a professional services firm, a trading business or a small manufacturer, the practical scope is usually narrower than feared: employees, customers, vendors, and whatever a website collects. For anyone running a consumer app, a healthcare or education service, or a business built on customer data, it is considerably wider.

What full compliance requires

From 12 May 2027, the substantive obligations include:

  • Notice — a clear, standalone statement to the individual of what personal data is collected, the purpose, and how to withdraw consent or complain. Notice buried inside general terms and conditions does not meet the standard.
  • Consent — free, specific, informed, unconditional and unambiguous, with a clear affirmative action, and as easy to withdraw as it was to give. Pre-ticked boxes and bundled consent do not qualify.
  • Purpose limitation and data minimisation — collect only what is necessary for the stated purpose, and use it only for that purpose.
  • Retention and erasure — delete personal data once the purpose is served, unless retention is required by another law. This is the obligation that most often collides with existing practice, because businesses tend to retain indefinitely by default.
  • Reasonable security safeguards — an express obligation, and the one carrying the highest penalty ceiling.
  • Breach notification — intimation to the Board and to affected data principals, with detailed particulars to follow within the short window the Rules prescribe (commonly cited as 72 hours). This requires a rehearsed process, not an intention.
  • Data principal rights — access, correction, erasure, grievance redressal and nomination, each needing an actual mechanism and a named point of contact.
  • Processor contracts — processing through a vendor must be under a valid contract, which means reviewing agreements with payroll providers, cloud services, CRM platforms and analytics tools.
  • Children's data — verifiable parental consent, and no tracking, behavioural monitoring or targeted advertising directed at children.

The Significant Data Fiduciary layer

Where a company is notified as an SDF, Section 10 adds:

  • a Data Protection Officer based in India, answerable to the board or governing body;
  • an independent data auditor to evaluate compliance; and
  • under Rule 13, a Data Protection Impact Assessment and audit once every twelve months, with the person carrying it out furnishing a report of significant observations to the Board.

Two honest observations about this. It applies only to entities actually notified as significant — it is not a size test a company can self-apply. And neither the Act nor the Rules as notified prescribe a professional qualification for the independent data auditor; what they stipulate is independence, which means an internal audit function cannot perform it. That leaves the role open in a way that will likely be clarified by practice or further rules.

The penalties

The Schedule sets maximum penalties, not fixed ones:

ContraventionCeiling
Failure to take reasonable security safeguards₹250 crore
Failure to notify a personal data breach₹200 crore
Contravention of children's data obligations₹200 crore
SDF failure on additional obligations₹150 crore
Other contraventions, including data principal duties and residuaryup to ₹50 crore

The Board determines quantum having regard to the nature, gravity and duration of the contravention, the type of data affected, whether it was repetitive, and what remedial action was taken. Prompt remediation is expressly a mitigating factor — which is an argument for having a documented process before anything goes wrong, not after.

Headline ceilings make for alarming reading and are unlikely to be the reality for a mid-size company with a first, promptly remediated lapse. The more probable near-term consequences are commercial: enterprise customers, lenders and acquirers asking about DPDP posture in diligence long before the Board ever does.

What is worth doing in the window that remains

In rough order of usefulness:

  1. Build a data inventory. What personal data you hold, where it sits, why you have it, who can see it, and who you send it to. Nothing else can be done properly without this, and it takes longer than expected.
  2. Set retention periods. Decide how long each category is kept and on what basis. Indefinite retention is the most common gap and one of the more visible ones.
  3. Review vendor contracts. Anywhere personal data goes to a third party — payroll, cloud, CRM, marketing — needs contractual footing.
  4. Fix notice and consent flows on your website, app and onboarding forms, including a working withdrawal mechanism.
  5. Write down a breach response process and rehearse it once. A tight reporting window is not survivable improvised.
  6. Tighten access. Who can reach personal data, and does anyone hold access they no longer need.

Point 6 will look familiar to anyone who has been through controls testing — it is the same question asked in IT general controls work, applied to a different category of data. Companies that have already documented access, change and retention for audit purposes are a good part of the way toward the data inventory, and the two exercises are worth running together rather than twice.

A note on scope

DPDP work spans three disciplines: legal (notices, contracts, lawful basis), technical (security architecture, encryption, logging), and governance and assurance (inventory, controls, testing, audit). No single adviser covers all three, and anyone suggesting otherwise should be treated carefully.

What is offered here is the third — readiness assessment, data inventory, controls design and testing, and retention and access review — alongside internal financial controls and IS audit work, which draws on the same evidence. Legal drafting of privacy notices and contracts, and technical security implementation, sit with a lawyer and your IT or security provider respectively.


The DPDP Act 2023 and the Rules notified on 13 November 2025 are new and largely untested, and further rules, clarifications and Board practice can be expected. This note reflects the position as at the date above and should be confirmed against the current text before it is relied on.

Frequently asked questions

Have the DPDP Rules actually been notified?

Yes. The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025, after a draft was released for consultation in January 2025. A limited set of provisions establishing the Data Protection Board took effect immediately; the substantive obligations follow on a phased timetable.

When do we actually have to comply?

Most substantive obligations — notice, consent, security safeguards, breach notification, data principal rights and the additional obligations of Significant Data Fiduciaries — commence on 12 May 2027, eighteen months from notification. Consent manager provisions commence earlier, on 12 November 2026. The Data Protection Board itself is already constituted.

Does DPDP apply to a small private company?

There is no turnover or headcount threshold in the Act. It applies to the processing of digital personal data, so a company with an employee database, a customer list or a website collecting enquiries is within scope. What differs by size is the depth of what is proportionate, and whether the company is notified as a Significant Data Fiduciary — which carries a further layer of obligations.

What is a Significant Data Fiduciary?

A Data Fiduciary notified as significant by the Central Government, based on factors including the volume and sensitivity of personal data processed and risks to data principals. Under Section 10 it carries additional obligations: an India-resident Data Protection Officer, an independent data auditor, and an annual Data Protection Impact Assessment and audit, with significant observations reported to the Board. These obligations commence with the rest of the substantive provisions.

Who can act as an independent data auditor?

The Act requires a Significant Data Fiduciary to appoint an independent data auditor to evaluate its compliance, and the Rules require the DPIA and audit annually with a report of significant observations to the Board. Neither the Act nor the Rules as notified prescribe a specific professional qualification for that role — what is stipulated is independence from the entity being audited, which means an internal audit function does not satisfy it.

What are the penalties?

The Schedule to the Act sets maximum penalties: up to ₹250 crore for failure to take reasonable security safeguards, up to ₹200 crore for failure to notify a breach, up to ₹200 crore for contravention of the children's data obligations, up to ₹150 crore for a Significant Data Fiduciary's failure on its additional obligations, and up to ₹50 crore in other cases. These are ceilings, not fixed amounts — the Board determines quantum having regard to the nature, gravity and duration of the contravention and the remedial action taken.

Working out what DPDP means for your business?

Send a note on what personal data you collect, the systems it sits in, and who you share it with. A readiness view of where the gaps are comes before any engagement is scoped.

Related service: Internal Controls & IS Audit